Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 325

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
A tax break for preserving land has drawn IRS scrutiny. Here’s when it still makes sense
Google slapped with $1 billion fine under landmark EU digital law
Cyclospora outbreak tests RFK Jr.'s promise to overhaul food system, rebuild trust in CDC
Tech reporter Joanna Stern asked AI to do 'almost everything' for a year—the No. 1 tool she'll keep using
UniCredit CEO tells CNBC acquisition of Commerzbank could happen in fourth quarter
Dow tumbles 500 points as Brent crude tops $100, Alphabet and Tesla drop: Live updates
Tesla misses on earnings, as free cash flow turns negative and margins slide
American Airlines stock tumbles 8% as fuel spike further postpones turnaround
Looking for Good Noodle Bar around West Hollywood
10-year Treasury yield rises to highest since January 2025 as surging oil rekindles inflation fear